Security Groups between 2 W2K trees on 1 single frest

From: Xavier Mercy (windows-net@fr.st)
Date: 12/06/02


From: "Xavier Mercy" <windows-net@fr.st>
Date: Thu, 5 Dec 2002 23:37:50 -0800


Hello,

>I have a single forest with multiple trees and domains
>(each remote site has its own tree).
>My W2K forest works on Native Mode.

Ok

>On my root domain, I've created a "Global Security" Group
>but I Can't add any other domain security Group.

What do you mean, you want another Global Security group
to member of this group?
In this case, Remember that, you can only add a Global
Group from the SAME DOMAIN

>Is there any way to perform the restriction ?

As far as as know, you can use Universal Groups or
continue to embed global groups in local groups

>Is there any know issue or restriction which impact my
>settings ?
>Thanks for your help.

PleaseL et me knows if this works

Xavier Mercy



Relevant Pages

  • Re: Restricting few users only to logon to a PC in a Windows 2003
    ... You can still do what Brian said... ... Define a Local security Group for the PC, then create a Domain Security Group, make the domain security group member of that local security group, use the policy to allow logon locally that Local Security group. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Permissions on a group
    ... The Group is a universal security group, ... > domain as the manager. ... > you have a large forest. ... >> this permission to lives in DomainB, when i try and make this user the ...
    (microsoft.public.exchange.admin)
  • Re: Security Groups
    ... Did you create a forest trust and which kind of trust do you create? ... I have created a (Domain Local Security Group) and (Global Security ... it should not allow me grant permissions to (Domain Local ...
    (microsoft.public.windows.server.active_directory)
  • Re: forest trust issue: The domain controllers required to find the se
    ... Creating a Security group in your forest then add the users from the other ... Ensure the domain controllers are available, and try to select the objects ... We have DNS forwarders all set up for their domain and DNS suffiz ...
    (microsoft.public.windows.server.active_directory)
  • Re: Forest-Issues
    ... I am performing the administration work directly from the Windows 2003 Domain Controllers. ... I am only able to import/add a HQ Enterprise Admin Security Group - Global into the Retail Administrator Security Group - Domain Local. ... Global groups can only contain members of its own domain, but can be assigned anywhere in the forest. ...
    (microsoft.public.windows.server.active_directory)